Scammers built an entire counterfeit blockchain impersonating GIWA, the Upbit-backed Ethereum layer-2 network, and used it to steal more than $2 million in Ether from over 1,300 wallets — exploiting a subtle trust assumption in how wallets connect to EVM networks.
The fake network appeared to be GIWA's anticipated mainnet: it had a working RPC endpoint, a cross-chain bridge, and Chain ID 9134, the identifier associated with the planned launch. The only problem was that GIWA's mainnet was not live. GIWA said claims that its production RPC had leaked were false because no mainnet RPC exists; its documentation lists only GIWA Sepolia, which uses Chain ID 91342, while the production network remains under development.
The scheme worked well enough to fool a seasoned DeFi project. DYORSWAP, whose community initially interacted with the purported network, later confirmed the chain was fraudulent: "The fake network used the correct GIWA Chain ID (9134), which made it appear legitimate during our initial verification."
Thirteen Hours of Patience, One Transaction
On-chain analysis by pseudonymous analyst Stablemark, reviewed by CryptoSlate, reconstructed the operation's timeline. Wallets tied to the scheme were funded through exchange service ChangeHero on September 26. About eleven hours later, the Safe wallet controlling the operation and the fake bridge went live. Over the next thirteen hours, 1,333 wallets deposited a combined 767 ETH.
Then the operators changed the bridge's portal code and drained 766 ETH — nearly the full balance — in a single on-chain transaction. The Seoul Economic Daily and Cryptonomist corroborated the incident details.
The stolen ETH has since begun to move: Stablemark reported 177 ETH routed through Tornado Cash, while the remaining 589 ETH sat across four wallets at the time of his update — still visible on-chain, but with the window for freezing narrowing.
Why the Chain ID Trick Works
The attack exploits a gap in how EVM networks are identified. A Chain ID tells a wallet which network it is connected to and protects against replay attacks across chains — but it verifies nothing about who controls the RPC endpoint or the bridge behind that identifier. Because scammers used GIWA's expected production Chain ID, the fake environment appeared consistent with the real network that users and tools were anticipating. The technique is effectively unpatchable at the protocol level; the defense is verifying infrastructure provenance — official endpoints, official announcements — rather than trusting identifiers alone.
The target choice was deliberate. GIWA is being developed by Dunamu, operator of South Korea's largest exchange Upbit, as the first "Self-Managed OP Enterprise" chain built on Optimism's OP Stack — a high-visibility launch with an eager community primed to bridge early. Anticipation of a mainnet is precisely the window a fake-chain campaign needs.
Partial Compensation, With a Warning
DYORSWAP has moved to soften the blow for its affected users. Wallets that bridged less than 5 ETH will receive compensation equal to 40% of their cross-chain amount; claims above 5 ETH are handled separately with identity and address verification, because the project said some larger wallets could themselves be linked to phishing or other fraudulent activity. It also published a compensation distribution address and warned victims to verify it through official channels — noting the obvious risk of a second wave of fake reimbursement scams targeting the first wave's victims.
For everyone else, the lesson predates blockchain: an infrastructure identifier is not an authenticity check. Until GIWA's real mainnet ships, any "GIWA" asking for deposits is, by definition, fake.
TrustGrade tracks the security posture of platforms and protocols in digital assets. Verified trust data: trustgrade.ai.